CVE-2026-42238·Docker vulnerability
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, nginx-ui exposes a backup restore endpoint (POST /api/restore) that is completely unauthenticated during the first 10 minutes after process startup on any fresh installation. An unauthenticated remote attacker can upload a crafted backup archive that overwrites the application's configuration file (app.ini) and SQLite database. Because the attacker controls the restored app.ini, they can inject an arbitrary OS command into the TestConfigCmd setting. After the application automatically restarts to apply the restored config, a single follow-up request triggers that command as the user running nginx-ui — typically root in Docker deployments. This issue has been patched in version 2.3.8.
- Severity
- critical
- Software
- Docker
- Fixed in
- 2.3.8
- Published
- 2026-05-04
Affected versions
Until: 2.3.8
Fixed in: 2.3.8
How to fix this CVE
Update Docker to version 2.3.8 or later to patch the unauthenticated backup restore endpoint that could allow remote code execution. This vulnerability affects nginx-ui deployments running on Docker, particularly those exposed on networks without proper authentication controls. Immediately upgrade your Docker installation and verify that the nginx-ui component is at version 2.3.8 or newer.
sudo dnf update docker-ceDefensia detects this vulnerability
What an exploitation attempt looks like
Sample log line indicative of exploitation attempts:
POST /api/restore HTTP/1.1.*Content-Type: multipart/form-data.*backup\.tar\.gz|POST /api/restore.*401|403|POST /api/restore.*200.*within first 600 seconds of container startupWAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Block or require authentication for POST requests to /api/restore endpoint; implement a WAF rule requiring valid API tokens or mutual TLS certificates for backup restore operations; rate-limit POST requests to /api/restore to maximum 1 request per minute per source IPHow to check if you are affected
- Run 'docker --version' and 'docker ps' to list running containers and identify any nginx-ui instances
- Inside a nginx-ui container, check the version with 'curl http://localhost:PORT/api/version' or inspect logs with 'docker logs <container-id>'
- Search Docker host logs for POST requests to /api/restore endpoint: 'grep -r "POST /api/restore" /var/lib/docker/containers/*/*/logs'
- Verify the fix by confirming nginx-ui version is 2.3.8+ and check the app.ini configuration file has not been modified by unauthorized parties: 'docker exec <container-id> cat /path/to/app.ini'
Indicators of compromise
- POST /api/restore endpoint without authentication headers
- Backup files (*.tar.gz) uploaded to nginx-ui during application startup window
- Modified app.ini configuration with TestConfigCmd containing shell metacharacters or suspicious binaries
FAQ
What is CVE-2026-42238?
This vulnerability allows an unauthenticated attacker to upload a malicious backup file to nginx-ui during the first 10 minutes after startup, enabling arbitrary OS command execution by injecting commands into the configuration file that runs as the container user (often root).
Is CVE-2026-42238 being actively exploited?
No, this CVE is not currently listed on the CISA Known Exploited Vulnerabilities catalog, and no public exploits have been released.
What versions of Docker are affected by CVE-2026-42238?
All Docker versions prior to 2.3.8 that include nginx-ui are affected; the vulnerability specifically targets nginx-ui running on Docker deployments.
How do I check if my server is vulnerable to CVE-2026-42238?
Run 'docker ps' to list containers, then 'docker exec <container-id> nginx-ui --version' or check the application logs for version information; if the version is below 2.3.8, the system is vulnerable.
Does Defensia detect CVE-2026-42238?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Docker is installed on a monitored server, CVE-2026-42238 will appear in your dashboard with remediation steps.
Related Docker CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-42238. Free for 1 server.
Get started free